VendorsIBMmaximo_application_suiteany version
Vulnerabilities

IBM Maximo Application Suite any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2025-36386
There is a vulnerability in the IBM Maximo Manage application in IBM Maximo Application Suite for Cognos Analytics
Published 2025-10-28 · Analyzed
9.8EPSS 0.005
CVE-2023-47718
IBM Maximo Asset Management cross-site request forgery
Published 2024-01-19 · Modified
8.8EPSS 0.003
CVE-2025-1500
IBM Maximo Application Suite file upload
Published 2025-04-05 · Analyzed
8.0EPSS 0.003
CVE-2023-43037
IBM Maximo Application Suite improper access control
Published 2025-04-10 · Analyzed
6.5EPSS 0.003
CVE-2021-29743
IBM Maximo Asset Management 7.6.0 and 7.6.1 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 201693.
Published 2021-08-30 · Modified
6.4EPSS 0.005
CVE-2024-38314
IBM Maximo Application Suite - Monitor Component information disclosure
Published 2024-10-24 · Analyzed
5.9EPSS 0.003
CVE-2023-32337
IBM Maximo Spatial Asset Management server-side request forgery
Published 2024-01-19 · Modified
5.4EPSS 0.003
CVE-2026-18531
IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret
Published 2026-08-05 · Analyzed
5.3EPSS 0.004
CVE-2024-35144
IBM Maximo Application Suite information disclosure
Published 2025-01-25 · Analyzed
5.3EPSS 0.003
CVE-2024-35150
IBM Maximo Application Suite log manipulation
Published 2025-01-25 · Analyzed
5.3EPSS 0.003
CVE-2026-15656
IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret
Published 2026-08-05 · Analyzed
4.3EPSS 0.002
CVE-2026-4820
IBM Maximo Application Suite was vulnerable to because Cookie ltpatoken2_<workspace_name> was not set with secure flag
Published 2026-04-01 · Analyzed
4.3EPSS 0.002
CVE-2025-14684
IBM Maximo Application Suite - Monitor Component uses Log Forging which is vulnerable to .
Published 2026-03-25 · Analyzed
4.0EPSS 0.001